TY - GEN
T1 - Grain-128AEADv2: Strengthening the Initialization Against Key Reconstruction
AU - Hell, Martin
AU - Johansson, Thomas
AU - Maximov, Alexander
AU - Meier, Willi
AU - Yoshida, Hirotaka
PY - 2021/12/9
Y1 - 2021/12/9
N2 - Properties of the Grain-128AEAD key re-introduction, as part of the cipher initialization, are analyzed and discussed. We consider and analyze several possible alternatives for key re-introduction and identify weaknesses, or potential weaknesses, in them. Our results show that it seems favorable to separate the state initialization, the key re-introduction, and the A/R register initialization into three separate phases. Based on this, we propose a new cipher initialization and update the cipher version to Grain-128AEADv2. It can be noted that previously reported and published analysis of the cipher remains valid also for this new version.
AB - Properties of the Grain-128AEAD key re-introduction, as part of the cipher initialization, are analyzed and discussed. We consider and analyze several possible alternatives for key re-introduction and identify weaknesses, or potential weaknesses, in them. Our results show that it seems favorable to separate the state initialization, the key re-introduction, and the A/R register initialization into three separate phases. Based on this, we propose a new cipher initialization and update the cipher version to Grain-128AEADv2. It can be noted that previously reported and published analysis of the cipher remains valid also for this new version.
U2 - 10.1007/978-3-030-92548-2_2
DO - 10.1007/978-3-030-92548-2_2
M3 - Paper in conference proceeding
SN - 978-3-030-92547-5
T3 - Lecture Notes in Computer Science
SP - 24
EP - 41
BT - Cryptology and Network Security
PB - Springer
T2 - 20th International Conference, CANS 2021
Y2 - 13 December 2021 through 15 December 2021
ER -